<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Security</title>
 <link>http://www.securityprocedure.com/tag/security</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>IT Risk Assessment Report and Template Toolkit</title>
 <link>http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit</link>
 <description>&lt;p&gt;Download Free IT Risk Assessment Report and Template Toolkit&lt;br /&gt;
&lt;IMG SRC=&quot;/files/it-risk-assessment-report.png&quot; alt=&quot;IT Risk Assessment Report&quot;&gt;&lt;br /&gt;
This templates including Risk Register and IT Control for selected risk criteria such as:&lt;br /&gt;
&lt;b&gt;Risk Assessment Matrix:&lt;/b&gt;&lt;br /&gt;
- Vulnerability&lt;br /&gt;
- Threat&lt;br /&gt;
- Risk&lt;br /&gt;
- Risk Sumary&lt;br /&gt;
- Risk Likelihood&lt;br /&gt;
- Rating&lt;br /&gt;
- Risk&lt;br /&gt;
- Impact&lt;br /&gt;
- Rating&lt;br /&gt;
- Overall Risk Rating&lt;br /&gt;
- Analysis ofRelevant Controls and Other Factors&lt;br /&gt;
- Recommendations&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/it-risk-assessment-report-and-template-toolkit#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/risk-assessment">Risk Assessment</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/it-risk-assessment-report.png" length="20349" type="image/png" />
 <pubDate>Tue, 02 Mar 2010 13:17:18 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">301 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Complete list of free Web Application Security Scanner</title>
 <link>http://www.securityprocedure.com/complete-list-free-web-application-security-scanner</link>
 <description>&lt;p&gt;Complete list of Free Download Open Source Web Application Security Scanner Tools&lt;/p&gt;
&lt;p&gt;&lt;b&gt;1. Grabber by Romain Gaucher&lt;/b&gt;&lt;br /&gt;
&lt;a href=&quot;http://rgaucher.info/beta/grabber/&quot; title=&quot;http://rgaucher.info/beta/grabber/&quot;&gt;http://rgaucher.info/beta/grabber/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Grabber is a web application scanner. Basically it detects some kind of vulnerabilities in your website. Grabber is simple, not fast but portable and really adaptable. This software is designed to scan small websites such as personals, forums etc. absolutely not big application: it would take too long time and flood your network. Grabber is a very small application (currently 2.5kLOC in Python) and the first reason of this scanner is to have a &quot;minimum bar&quot; scanner for the Samate Tool Evaluation Program at NIST. Grabber is also for me a nice way to do some automatics verification on websites/scripts I do. Users should know some things about web vulnerabilities before using this soft because it only tell you what vulnerability it is... not how to solve it. &lt;/p&gt;
&lt;p&gt;&lt;b&gt;2. Grendel-Scan by David Byrne and Eric Duprey&lt;/b&gt;&lt;br /&gt;
&lt;a href=&quot;http://grendel-scan.com/&quot; title=&quot;http://grendel-scan.com/&quot;&gt;http://grendel-scan.com/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Grendel-Scan is an open-source web application security testing tool. It has automated testing module for detecting common web application vulnerabilities, and features geared at aiding manual penetration tests. The only system requirement is Java 5; Windows, Linux and Macintosh builds are available.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;3. Paros by Chinotec&lt;/b&gt;&lt;br /&gt;
&lt;a href=&quot;http://parosproxy.org/&quot; title=&quot;http://parosproxy.org/&quot;&gt;http://parosproxy.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Paros is for people who need to evaluate the security of their web applications. It is free of charge and completely written in Java. Through Paros&#039;s proxy nature, all HTTP and HTTPS data between server and client, including cookies and form fields, can be intercepted and modified.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/complete-list-free-web-application-security-scanner&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/complete-list-free-web-application-security-scanner#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/checklists">Checklists</category>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/mobile-security">Mobile Security</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/wireless-security">Wireless Security</category>
 <pubDate>Sat, 12 Dec 2009 14:00:11 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">300 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download IT General Control (ITGC) Audit Program Template</title>
 <link>http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img502.imageshack.us/img502/2408/itgc.jpg&quot; alt=&quot;ITGC IT General Control&quot;&gt;&lt;br /&gt;
So basically what is the simplest approach for ITGC? do we should check every changes and modification in our application and infrastructure? or do we should only focus to significant one? The simplest approach is by using minimum requirement by the government/regulation. So here is some scope of ITGC based on Sarbanes Oxley Section 404&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Program Development Program Change&lt;/b&gt;&lt;br /&gt;
Acquire or develop application software	The organization&#039;s system development life cycle (SDLC) includes security, availability and processing integrity requirements of the organization.&lt;/p&gt;
&lt;p&gt;Acquire or develop application software	An adequate SDLC methodology has been established to serve as a basis for controlling development and maintenance activities, and the SDLC methodology is consistent with business and end-user strategies and objectives.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Logical Access&lt;/b&gt;&lt;br /&gt;
Ensure systems security	An information security policy exists and has been approved by an appropriate level of executive management.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-it-general-control-itgc-audit-program-template#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/sarbanes-oxley">Sarbanes Oxley</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/ITGeneralControl.xls" length="29184" type="application/vnd.ms-excel" />
 <pubDate>Sat, 28 Feb 2009 01:11:27 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">296 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Eleven golden rules for user registration controls</title>
 <link>http://www.securityprocedure.com/eleven-golden-rules-user-registration-controls</link>
 <description>&lt;p&gt;ISO27002 recommends that an organization’s user registration process should cover the following:&lt;br /&gt;
1. Unique user identifications (IDs) should be issued so that users can be linked to, and made responsible for, their actions. &lt;/p&gt;
&lt;p&gt;2. The user’s access rights should be documented and describe what assets and systems the user is allowed to access. &lt;/p&gt;
&lt;p&gt;3. System owners should authorize proposed users to use the system, and the access rights document should also be authorized by the individual’s line manager, to ensure that it is appropriate.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/eleven-golden-rules-user-registration-controls&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/eleven-golden-rules-user-registration-controls#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Sat, 21 Feb 2009 23:49:36 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">295 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Network Security Service Level Agreement (SLA) Sample Templates</title>
 <link>http://www.securityprocedure.com/download-network-security-service-level-agreement-sla-sample-templates</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img5.imageshack.us/img5/7025/slaan1.jpg&quot;&gt;&lt;br /&gt;
Below sample service level agreement (SLA) for supporting security event feeds from network devices. This sample SLA is arranged between the network support team (NetEng) and the team to whom security monitoring is assigned (InfoSec).&lt;/p&gt;
&lt;p&gt;The purpose of this document is to clarify support responsibilities and expectations. Specifically, it outlines:&lt;br /&gt;
- Services provided by NetEng to support network security event recording for monitoring and incident response&lt;/p&gt;
&lt;p&gt;- General levels of response, availability, and maintenance associated with these services&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-network-security-service-level-agreement-sla-sample-templates&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-network-security-service-level-agreement-sla-sample-templates#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/documents">Documents</category>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/templates">Templates</category>
 <enclosure url="http://www.securityprocedure.com/files/service-level-agreement-information-security-and-network-engineering.doc" length="49664" type="application/msword" />
 <pubDate>Sat, 14 Feb 2009 18:32:53 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">294 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Three  Security Approaches for SOA</title>
 <link>http://www.securityprocedure.com/three-security-approaches-soa</link>
 <description>&lt;p&gt;&lt;b&gt;Message-level security&lt;/b&gt;&lt;br /&gt;
SOA brings changes in the requirements for data confidentiality and data integrity. When a message sent to party 1 (brokerage) contains parts intended for party 2 (bank), we need the ability to differently encrypt and/or sign the part that is intended for use only by party 2. Clearly, traditional transport layer security mechanisms such as SSL/TLS are not good enough here, as they cannot stop party 1 from reading and/or tampering with the message part intended for party 2.&lt;/p&gt;
&lt;p&gt;Message-level security (as opposed to transport-level security) is a new approach to solve this problem. With this approach, different parts of a message can be protected differently, to make them usable only by intended parties in the message path. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/three-security-approaches-soa&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/three-security-approaches-soa#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/service-oriented-architecture">Service Oriented Architecture</category>
 <pubDate>Sat, 20 Dec 2008 14:15:44 -0800</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">287 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Download Free Folder Lock from Free Folder Hider 10.5</title>
 <link>http://www.securityprocedure.com/download-free-folder-lock-free-folder-hider-105</link>
 <description>&lt;p&gt;&lt;IMG SRC=&quot;http://img81.imageshack.us/img81/3327/201722largeamm8.png&quot; align=&quot;left&quot; hspace=&quot;5&quot;&gt;Download Free Folder Lock from Free Folder Hider 10.5. Almost every computer user keeps files that are personal, private and confidential, or important to be preserved as undeletable. You may have files that are inappropriate for kids or other family members, or files with valuable information that can be stolen. Such files and folders need security protection so that intruders or unauthorized users cannot access, read, view, copy, move or delete them. Folder Hider can hide and password-protect your files, folders, pictures, and documents in seconds. With Folder Hider, you can keep all the data you want to secure in a Privacy Area.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/download-free-folder-lock-free-folder-hider-105&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/download-free-folder-lock-free-folder-hider-105#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Sat, 20 Sep 2008 07:54:57 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">269 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>OECD Guidelines for the Security of Information Systems and Networks: Towards a Culture of Security</title>
 <link>http://www.securityprocedure.com/oecd-guidelines-security-information-systems-and-networks-towards-culture-security</link>
 <description>&lt;p&gt;These guidelines apply to all participants in the new information society and suggest the need for a greater awareness and understanding of security issues, including the need to develop a &quot;culture of security&quot; - that is, a focus on security in the development of information systems and networks, and the adoption of new ways of thinking and behaving when using and interacting within information systems and networks. The guidelines constitute a foundation for work towards a culture of security throughout society.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/oecd-guidelines-security-information-systems-and-networks-towards-culture-security&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/oecd-guidelines-security-information-systems-and-networks-towards-culture-security#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Mon, 11 Aug 2008 00:26:05 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">258 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Principles of Generally Accepted Information Security Principles (GAISP)</title>
 <link>http://www.securityprocedure.com/principles-generally-accepted-information-security-principles-gaisp</link>
 <description>&lt;p&gt;GAISP is based on a solid consensus-building process that is central to the success of this approach. Principles at all levels are developed by information security practitioners who fully understand the underlying issues of the&lt;br /&gt;
documented practices and their application in the real world. Then, these principles will be reviewed and vetted by&lt;br /&gt;
skilled information security experts and authorities who will ensure that each principle is: &lt;/p&gt;
&lt;p&gt;• Accurate, complete, and consistent&lt;br /&gt;
• Compliant with its stated objective&lt;br /&gt;
• Technically reasonable&lt;br /&gt;
• Well-presented, grammatically and editorially correct&lt;br /&gt;
• Conforms to applicable standards and guideline&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/principles-generally-accepted-information-security-principles-gaisp&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/principles-generally-accepted-information-security-principles-gaisp#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Wed, 06 Aug 2008 23:46:45 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">254 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>What is Generally Accepted System Security Principles (GASSP/GSSP)?</title>
 <link>http://www.securityprocedure.com/what-generally-accepted-system-security-principles-gasspgssp</link>
 <description>&lt;p&gt;Generally Accepted System Security Principles incorporate the consensus, at a particular time, as to the principles, standards, conventions, and mechanisms that information security practitioners should employ, that information processing products should provide, and that information owners should acknowledge to ensure the security of information and information systems.&lt;/p&gt;
&lt;p&gt;GASSP relates to physical, technical, and administrative information security and encompasses pervasive, broad functional, and detailed security principles. GASSP nomenclature considers the terms policy, rules, procedures, and practices to relate to the organizational implementation of security. Information technology (IT) changes rapidly, and GASSP are expected to evolve accordingly. Consensus regarding accepted information security principles is achieved first within the GASSP Committee followed by international IT community review.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;GAAP versus GASSP?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/what-generally-accepted-system-security-principles-gasspgssp&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/what-generally-accepted-system-security-principles-gasspgssp#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <category domain="http://www.securityprocedure.com/tag/security-management">Security Management</category>
 <pubDate>Mon, 04 Aug 2008 19:39:13 -0700</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">253 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>

